As long as you have a valid backup of your original firmware, you can restore your C7 by following these instructions.
But, before you go any further, double check the contents of your backup at address 0x00001000 (like with a Hex Editor). If that byte contains 0xFF, then your backup is invalid and will brick your C7 again, so STOP! I will address this situation in another post soon.
OK now, first of all, you'll need the following gear:
1. A Bus Pirate
2. A Bus Pirate Probe cable
3. A Pomona 5250 SOIC Clip
Do not substitute the 3M part for the Pomona, as it won't work. The Bus Pirate is an inexpensive hacker's tool that can serve as an external chip programmer. It's supported by flashrom and although painfully slow, it does the job quite well. It all cost me ~$60 including shipping.
This presentation will provide a good step-by-step guide to disassembling your C7 to get access to the EEPROM which is on the top side of the motherboard
(MB), under the keyboard. It looks like a horrible nightmare, but thanks to these guys, it really isn't too difficult. However, I do recommend disconnecting both the keyboard and the trackpad, their cables and connectors are too fragile to risk leaving connected, IMHO. I will admit that reconnecting them is a royal PITA, though.
https://docs.google.com/file/d/0Bzig09VSdjW1azRKaEtqZk5MZW8/edit?usp=sharing
Here's an ASCII diagram detailing how to connect the Bus Pirate (BP) to the C7's EEPROM.
TXT
PNG
On my MB, the chip is a Macronix MX25L6406E, but yours might differ. You should also be aware that there's more than one probe cable design and the color schemes vary. I'm using the Seeed Studio probe cable design. For more info on the BP, consult:
http://dangerousprototypes.com/docs/Bus_Pirate
For instructions on programming the EEPROM, consult this authority:
http://johnlewis.ie/unbricking-a-samsung-series-5-550-chromebook/
He's using a Samsung 550 Chromebook, but the procedure is the same. The C7's battery pack is, of course, removable. So, as long as the battery is disconnected, it's already "cut."
Showing posts with label John Lewis. Show all posts
Showing posts with label John Lewis. Show all posts
Friday, September 20, 2013
Tuesday, September 17, 2013
Important Discovery to Prevent Bricking
Through rigorous application of the experimental method, I have discovered that (at least on the C7) a valid backup of the firmware is only possible with hardware (HW) write-protect (WP) disabled. In this context, software (SW) WP seems to be irrelevant.
To clarify, if you use flashrom to read the EEPROM without bridging the WP jumper on the motherboard first, that backup copy of the firmware will be invalid. If you subsequently flash that backup (or a modded version of it) onto the EEPROM, it will brick the device.
Does this make any sense? No, but it appears to be a fact. Apparently, with HW WP enabled flashrom just silently (no error messages) fails to read the Intel Management Engine (and possibly other) code in the firmware image. I have found references to the fact that Google patched flashrom so that it would not crash under these conditions, but have no idea why. I would have preferred that it crash, rather than silently create an invalid image of the firmware. Of course, I must acknowledge that these tools were never intended for use by the consumer.
With this knowledge, I have successfully enabled the Dev Mode Boot Screen bypass with the stock firmware. So I can now confirm that "the hack" can be performed safely, as long as you keep this fact in mind. But, be aware that some of the instructions on the web do not take this into account and if followed to the letter, will brick your C7. I recommend only this source:
http://johnlewis.ie/neutering-the-developer-mode-screen-on-your-chromebook/
John's information was essential in my effort to de-brick my C7. He's using a Samsung 550 Chromebook, but the platforms are similar enough in this case.
To clarify, if you use flashrom to read the EEPROM without bridging the WP jumper on the motherboard first, that backup copy of the firmware will be invalid. If you subsequently flash that backup (or a modded version of it) onto the EEPROM, it will brick the device.
Does this make any sense? No, but it appears to be a fact. Apparently, with HW WP enabled flashrom just silently (no error messages) fails to read the Intel Management Engine (and possibly other) code in the firmware image. I have found references to the fact that Google patched flashrom so that it would not crash under these conditions, but have no idea why. I would have preferred that it crash, rather than silently create an invalid image of the firmware. Of course, I must acknowledge that these tools were never intended for use by the consumer.
With this knowledge, I have successfully enabled the Dev Mode Boot Screen bypass with the stock firmware. So I can now confirm that "the hack" can be performed safely, as long as you keep this fact in mind. But, be aware that some of the instructions on the web do not take this into account and if followed to the letter, will brick your C7. I recommend only this source:
http://johnlewis.ie/neutering-the-developer-mode-screen-on-your-chromebook/
John's information was essential in my effort to de-brick my C7. He's using a Samsung 550 Chromebook, but the platforms are similar enough in this case.
Subscribe to:
Posts (Atom)
